How Blogged handles personal information

Privacy Policy

This policy explains the personal information Blogged collects, why it is used, who receives it, how long it is kept, and the choices available to you.

Effective August 20, 202614 min read
Blogged combines autonomous content generation, web research, hosted publishing, and customer-directed integrations. This policy explains how those functions affect your rights and responsibilities.

1. Scope and our role

Blogged is a product owned and operated by BoostYard LLC, a Delaware limited liability company. In this policy, “Blogged,” “we,” “us,” and “our” mean BoostYard LLC.

This Privacy Policy applies to Blogged's marketing website, documentation, account and workspace experience, support communications, billing relationship, and the services used to research, create, optimize, schedule, host, and measure customer content. It does not replace the privacy notice of a Blogged customer whose published blog you visit.

Blogged is a controller or business for account, billing, support, security, and marketing-site information that it determines how to use. When Blogged hosts a customer's blog or processes its subscribers, leads, content, private knowledge, analytics, or publication instructions, the customer is normally the controller or business and Blogged acts as its processor or service provider. The Data Processing Addendum governs that processing.

Customer blogs

The customer decides what to publish, what forms and calls to action to use, whether to add analytics or advertising tags, and what privacy notice applies to its readers. Direct privacy requests about a customer's blog should normally go to that customer first.

2. Information we collect

CategoryExamplesSources
Account and workspaceName, work email, authentication identifiers, profile details, workspace membership, role, and SaaS URLYou, your workspace administrator, Firebase Authentication, and Google Sign-In when selected
Customer content and instructionsProduct descriptions, strategy, topics, briefs, drafts, posts, revisions, sources, uploaded documents, knowledge facts, competitors, images, brand settings, publication schedules, prompts, and feedbackYou, authorized workspace members, customer-approved public sources, and product workflows
Publishing and integration dataDomains, DNS verification state, blog settings, Search Console property data, OAuth scopes and encrypted tokens, tracker IDs, custom code, webhook settings, and delivery resultsYou, your connected services, your website, and service providers
Billing and commercialPlan, usage, trial eligibility, subscription status, invoices, billing address, tax status, promotion codes, payment outcome, and Stripe customer or subscription identifiersYou, your workspace, and Stripe. Blogged does not receive full payment-card numbers
Support and communicationsMessages, requests, survey or feedback responses, billing-notice delivery, bounce and complaint status, and related account contextYou, your team, and communications providers
Device, usage, and securityIP address, browser and device data, timestamps, page or feature interactions, logs, error details, authentication events, rate-limit records, and anti-abuse signalsYour browser, device, network, and Blogged systems. Some rate-limit records store a one-way hash of the IP address
Customer-blog reader dataSubscriber email, lead-form data, consent or preference state, on-site searches, reader feedback, CTA views and clicks, campaign parameters, and page-level engagement eventsReaders of customer blogs, under the customer's configuration and instructions

Please do not submit government identifiers, payment-card data, health information, biometric data, precise location, or other sensitive personal information to prompts, briefs, knowledge, uploads, custom code, or support unless Blogged has expressly agreed in writing that the use is supported.

3. How we use information

  • Provide and operate accounts, workspaces, projects, the Editor, Knowledge, Assets, Competitor Watch, Blog Site, Insights, and Autopilot.
  • Scan customer-directed public sources, perform web research, generate and review content and images, maintain knowledge provenance, and run publication safeguards.
  • Host blogs, serve previews, connect domains, publish or unpublish posts, process forms, deliver customer-configured webhooks, and measure content performance.
  • Authenticate users, maintain permissions, secure credentials, prevent fraud and abuse, rate-limit public endpoints, debug failures, and preserve service reliability.
  • Administer trials, subscriptions, taxes, invoices, plan allowances, cancellations, payment recovery, and transactional billing notices.
  • Answer support requests, communicate service and policy changes, and improve product usability and performance.
  • Meet legal obligations, enforce agreements, resolve disputes, and protect Blogged, customers, readers, and the public.

Where the GDPR or UK GDPR applies, the usual legal bases are performance of a contract, legitimate interests in operating and securing a business service, compliance with law, and consent where consent is required, including for certain cookies or connected services. You may withdraw consent without affecting processing that occurred before withdrawal.

4. AI, research, and autonomous publishing

Blogged sends the instructions and context needed for a task to Google Cloud's Vertex AI services. That context may include customer prompts, briefs, product facts, excerpts from approved sources, draft content, feedback, and image instructions. In production, Blogged uses Vertex AI under Google Cloud terms. Google states that it does not train or fine-tune its AI models on customer data without permission or instruction, although limited logging may occur for security and abuse monitoring under its terms.

Blogged uses Exa to search the public web for research and competitor context. Search queries should not contain personal or confidential information. Results and source excerpts may be stored with the relevant research, knowledge, or draft record so a customer can review provenance and publication decisions.

Full Autopilot can schedule and publish content when the customer has enabled it and the configured direction, eligibility, and governance checks pass. Assisted mode waits for human review. Blogged records workflow state, approvals, holds, revisions, and publication evidence to operate these controls and investigate failures.

5. Google account and Search Console data

If you connect Google Search Console, Blogged requests the scopes displayed during Google's authorization flow. Blogged uses that access to list and verify properties, read search performance and URL inspection information, synchronize reports, and, only when the granted scope allows and you request it, submit a sitemap. OAuth tokens are encrypted at rest. Disconnecting the integration revokes the token with Google and removes the active connection from Blogged.

Limited use

Blogged's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold, or used to train generalized AI models.

6. How information is disclosed

  • Service providers. Blogged uses providers for cloud hosting, authentication, storage, AI processing, public-web search, payment processing, transactional email, analytics, security, and related infrastructure. The current list is on the Subprocessor List.
  • Your workspace. Owners, admins, editors, and viewers receive access according to their role. Workspace owners and admins control membership and may access or export customer data within the product.
  • Customer-directed recipients. Blogged sends data to a tracker, custom script, lead webhook, connected Google property, domain provider, or other integration when the customer configures or requests that transfer.
  • Readers and the public. Published posts, author details, sources, media, blog settings, and other content selected for publication become public. Private previews use short-lived links but should still be shared carefully.
  • Professional advisers and authorities. Blogged may disclose information to auditors, insurers, lawyers, accountants, regulators, courts, or law enforcement when reasonably necessary and legally permitted.
  • Business transactions. Information may be transferred in connection with financing, due diligence, a merger, acquisition, reorganization, insolvency, or sale of assets, subject to appropriate confidentiality and notice requirements.

Blogged does not sell personal information for money. Blogged does not use customer content, private knowledge, Google user data, or customer-blog subscriber and lead data to advertise third-party products. After analytics consent, Google Analytics 4 and Microsoft Clarity process pseudonymous interaction data on Blogged's own marketing, documentation, and account surfaces for product analytics. Advertising storage, ad-user-data consent, ad personalization, Google signals, and ad-personalization signals remain disabled in Blogged's configuration. Each provider may also operate as an independent controller under its terms.

7. Customer-controlled trackers, forms, and webhooks

A customer may add Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, or custom head code to its published blog. The customer decides whether to use those tools and is responsible for a lawful basis, notice, consent, vendor terms, and honoring reader choices. Custom code executes in the blog page and may collect or disclose information independently of Blogged.

When enabled by the customer, Blogged's blog cookie banner describes the configured tag categories and stores the reader's accept or decline choice in local storage for 180 days. Do Not Track and Global Privacy Control disable customer-configured tags by default unless the customer deliberately overrides that setting. Blogged's first-party, aggregated reporting continues to honor those signals.

Customer-configured lead webhooks can send subscriber or lead details to the customer's endpoint. After delivery, the recipient's privacy practices govern its copy. Blogged applies destination validation and delivery controls, but the customer remains responsible for the endpoint, recipient, and requested fields.

8. Retention and deletion

Blogged keeps personal information for as long as needed to provide the service, maintain an active business relationship, comply with law, resolve disputes, protect security, and enforce agreements. Retention depends on the record and its purpose rather than one blanket period.

  • Account, workspace, project, content, knowledge, asset, publication, and integration records generally remain while the account or relevant project is active. Archiving a project pauses active work but is not deletion, and its published blog can remain online.
  • Short-lived previews expire after their configured lifetime. Operational jobs, leases, idempotency records, and some execution traces expire under service-specific schedules when they no longer support recovery or audit needs.
  • Billing, tax, invoice, contract, fraud-prevention, payment-recovery, and suppression records may be kept for legal, accounting, security, or deliverability obligations after service ends.
  • Unsubscribed customer-blog readers remain marked unsubscribed so the customer does not contact them again. Authorized customer users can permanently delete subscriber records in the product.
  • Deletion from active systems may not immediately remove encrypted backups, disaster-recovery copies, or records that law requires Blogged to retain. Those copies remain protected and age out under normal cycles.

Because the current product supports project archive and restore rather than full self-service account erasure, contact Blogged to request deletion of an account or workspace. Blogged will verify authority and explain any data that must be retained or that belongs to another workspace member or customer.

9. Security

Blogged uses technical and organizational safeguards designed for the nature of the service, including role-based workspace access, server-enforced tenant boundaries, encryption in transit, managed cloud encryption at rest, encrypted Search Console tokens, restricted secret storage, audit and revision records, rate limits, webhook destination validation, and monitoring. No internet service can guarantee absolute security.

You are responsible for protecting account credentials, assigning the minimum necessary workspace role, reviewing who can publish or configure executable code, and notifying Blogged promptly of suspected unauthorized access.

10. International transfers

Blogged and its providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws from your location. Where required, Blogged uses contractual protections such as the European Commission's Standard Contractual Clauses, the UK transfer addendum, provider data-processing terms, or another lawful transfer mechanism. More detail appears in the Data Processing Addendum and Subprocessor List.

11. Your privacy rights

Depending on your location and Blogged's role, you may have rights to access, know, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, opt out of certain disclosures, and appeal a decision. You may also complain to your local data-protection authority. Blogged will not discriminate against you for exercising a privacy right.

Send a request to hi@blogged.dev. Describe the account, workspace, blog, or email address involved and the right you want to exercise. Blogged may verify identity and authority before acting. If Blogged processes the information only for a customer, it may direct the request to that customer or help the customer respond.

12. California privacy notice

The table in Section 2 describes the categories of personal information collected during the preceding 12 months, the sources, and representative data elements. Sections 3 and 6 describe business purposes and recipient categories. Blogged may collect identifiers, customer records, commercial information, internet or electronic activity, professional information, approximate location derived from IP address, audio or visual content a user uploads, and inferences used to provide product strategy or security. Blogged does not intentionally collect sensitive personal information for inferring characteristics.

Blogged has not sold personal information for money. It has disclosed identifiers, commercial information, internet activity, and customer-directed content to service providers for the business purposes described here. To exercise rights to know, access, correct, delete, or obtain portability, use the contact method in Section 11. Analytics on Blogged's own surfaces remains off until the visitor explicitly allows it, and advertising consent remains denied. A Global Privacy Control signal is treated as an opt-out signal on supported analytics and customer-blog tracking surfaces. Blogged does not knowingly sell or share personal information of anyone under 16.

13. Children

Blogged accounts and autonomous content services are for business users who are at least 18 or the age of legal majority where they live. Blogged does not knowingly create accounts for children. Customer blogs are public websites controlled by customers; customers are responsible for ensuring their content, forms, trackers, and audience practices are appropriate for their intended readers.

14. Changes and contact

Blogged may update this policy as the service, providers, or law changes. The effective date at the top identifies the current version. Material changes will receive additional notice when required by law or when they materially change how existing account or Google user data is used.

For privacy questions or requests, contact BoostYard LLC at hi@blogged.dev or write to: BoostYard LLC, Attn: Privacy, 16192 Coastal Highway, Lewes, DE 19958, United States.

Questions about this policy?

Include the relevant workspace, customer blog, public URL, or account email so the request can be routed without collecting unnecessary information.

Email hi@blogged.dev

Related policies